Reference notes for the facts that CompTIA A+ questions depend on: ports and protocols, Wi-Fi standards, IP addressing, storage and RAID, memory, cloud and virtualization, Windows and Linux commands, and security procedures.
Aligned to 220-1201 & 220-1202 (V15)5 modules across Core 1 and Core 2Reviewed October 2026
How to read these notes: Items tagged Extra are not named in the V15 exam objectives but are common on the job and help you reason through related questions. Learn the objective items first. New to A+? Start with the exam overview for format, scoring, and domain weights.
Part 1 · Core 1 (220-1201)
Module 1: Networking protocols, ports, and standards
Know each port number, its transport protocol, what it does, and whether it is encrypted.
TCP/IP port reference
"Objective" means the port appears in the V15 Core 1 port list. "Encrypted" describes the protocol's default behavior.
Port
Protocol
Transport
Purpose
Encrypted
Scope
20, 21
FTP
TCP
File transfer; 20 carries data and 21 carries control commands
No
Objective
22
SSH, SFTP
TCP
Encrypted remote command-line access; SFTP transfers files over SSH
Yes (SSH)
Objective
23
Telnet
TCP
Legacy text-based remote terminal; replace with SSH
No
Objective
25
SMTP
TCP
Sending and relaying email between servers
No (STARTTLS optional)
Objective
53
DNS
UDP, TCP
Resolves names such as www.example.com to IP addresses; TCP is used for zone transfers and large responses
No
Objective
67, 68
DHCP
UDP
Automatic IP configuration; 67 is the server and 68 is the client
No
Objective
69
TFTP
UDP
Simple file transfer without authentication, used for PXE boot and device firmware
No
Extra
80
HTTP
TCP
Unencrypted web traffic
No
Objective
110
POP3
TCP
Downloads email to one client, usually removing it from the server
No (POP3S on 995)
Objective
123
NTP
UDP
Synchronizes clocks; time drift breaks Kerberos authentication and certificates
No
Extra
137–139
NetBIOS / NetBT
UDP, TCP
Legacy Windows name (137), datagram (138), and session (139) services
No
Objective
143
IMAP
TCP
Accesses mail that stays on the server and syncs across devices
No (IMAPS on 993)
Objective
161, 162
SNMP
UDP
Network device monitoring; 161 for queries and 162 for traps
Only SNMPv3
Extra
389
LDAP
TCP, UDP
Queries directory services such as Active Directory
No (LDAPS on 636)
Objective
443
HTTPS
TCP
Web traffic secured with TLS
Yes (TLS)
Objective
445
SMB / CIFS
TCP
Windows file and printer sharing
Optional (SMB 3.x)
Objective
514
Syslog
UDP
Sends system events to a central logging server
No
Extra
636
LDAPS
TCP
LDAP secured with TLS
Yes (TLS)
Extra
993
IMAPS
TCP
IMAP secured with TLS
Yes (TLS)
Extra
995
POP3S
TCP
POP3 secured with TLS
Yes (TLS)
Extra
3389
RDP
TCP, UDP
Microsoft graphical remote desktop
Yes (TLS)
Objective
Exam tip: TCP is connection-oriented, with a handshake, acknowledgments, and retransmission. UDP is connectionless and faster but does not guarantee delivery. Services that need quick, small exchanges, such as DHCP, TFTP, NTP, SNMP, and most DNS lookups, use UDP.
Wireless networking standards
Speeds are theoretical maximums. Real-world throughput is much lower.
Standard
Frequency
Max speed
What to remember
802.11a
5 GHz
54 Mbps
Legacy; less interference than 2.4 GHz but shorter range
802.11b
2.4 GHz
11 Mbps
Legacy; prone to interference from microwaves, cordless phones, and Bluetooth
802.11g
2.4 GHz
54 Mbps
Backward-compatible with 802.11b
802.11n (Wi-Fi 4)
2.4 GHz and 5 GHz
600 Mbps
Introduced MIMO (multiple-input multiple-output) and channel bonding
802.11ac (Wi-Fi 5)
5 GHz
~6.9 Gbps
Added downlink MU-MIMO and standardized beamforming
802.11ax (Wi-Fi 6 / 6E)
2.4, 5, and 6 GHz (6 GHz is Wi-Fi 6E)
~9.6 Gbps
Introduced OFDMA for dense environments; requires WPA3 on 6 GHz
802.11be (Wi-Fi 7) Extra
2.4, 5, and 6 GHz
~46 Gbps
320 MHz channels and multi-link operation (MLO)
Channel planning: In the 2.4 GHz band, use channels 1, 6, and 11 in North America because they do not overlap. The 5 GHz and 6 GHz bands offer many more non-overlapping channels, and wider channels (40, 80, or 160 MHz) increase speed but reduce the number of usable channels.
IP addressing quick reference
IPv4 addresses are 32 bits, written as four decimal octets. IPv6 addresses are 128 bits, written as eight groups of hexadecimal, and consecutive groups of zeros can be shortened once with ::.
Address type
Range
Private (Class A)
10.0.0.0/8
Private (Class B)
172.16.0.0/12 (172.16–172.31)
Private (Class C)
192.168.0.0/16
APIPA
169.254.0.0/16: the client could not reach a DHCP server
Loopback
127.0.0.1 (IPv4), ::1 (IPv6)
IPv6 link-local
fe80::/10, similar in purpose to APIPA
IPv6 global unicast
2000::/3, publicly routable
CIDR
Subnet mask
Usable hosts
/8
255.0.0.0
16,777,214
/16
255.255.0.0
65,534
/24
255.255.255.0
254
/25
255.255.255.128
126
/26
255.255.255.192
62
/27
255.255.255.224
30
/28
255.255.255.240
14
Usable hosts equal 2(32 − prefix) − 2, because the network and broadcast addresses cannot be assigned. A client with a 169.254.x.x address almost always points to a DHCP problem: check the cable, the switch port, the DHCP server or scope, and then run ipconfig /release and ipconfig /renew.
Module 2: Hardware architecture and storage
Interfaces set the speed ceiling; RAID levels set the balance between speed, capacity, and fault tolerance.
Storage interfaces and performance
SATA III: 6 Gbps link, about 550–600 MB/s in practice. Used by 2.5-inch SSDs, HDDs, and M.2 SATA drives.
NVMe: a protocol designed for flash storage that runs over PCIe lanes with many parallel command queues, giving far lower latency than SATA's AHCI.
Typical PCIe x4 NVMe drive speeds: Gen 3 up to ~3,500 MB/s, Gen 4 up to ~7,000–7,500 MB/s, Gen 5 up to ~14,000 MB/s.
SAS: enterprise drive interface with dual ports and higher reliability, common in servers.
Form factors and the M.2 trap
M.2 is a form factor, not a speed. An M.2 slot can support SATA, NVMe, or both, so check the motherboard manual.
Common M.2 sizes are written as width and length in millimeters, such as 2280 (22 mm × 80 mm).
mSATA is an older, smaller SATA form factor used in some laptops.
HDDs come in 3.5-inch (desktop) and 2.5-inch (laptop) sizes; spindle speeds such as 5,400 and 7,200 RPM affect performance.
N is the number of drives. Capacity assumes drives of equal size.
RAID level
Method
Minimum drives
Usable capacity
Fault tolerance
RAID 0
Striping
2
100% (N drives)
None; one failure loses all data
RAID 1
Mirroring
2
50%
Survives one drive failure in a two-drive mirror
RAID 5
Striping with distributed parity
3
N − 1 drives
Survives one drive failure
RAID 6
Striping with dual parity
4
N − 2 drives
Survives two simultaneous drive failures
RAID 10 (1+0)
Striped mirrors
4 (even numbers)
50%
Survives one failure per mirror pair
RAID is not a backup. It protects against drive failure, not accidental deletion, ransomware, or a failed controller. Keep separate backups, ideally following the 3-2-1 rule.
System RAM architecture
DDR generations are not interchangeable. The key notch prevents installing the wrong module.
Type
DIMM pins (desktop)
SODIMM pins (laptop)
Voltage
Key features
DDR3
240
204
1.5 V (1.35 V for DDR3L)
Legacy systems
DDR4
288
260
1.2 V
One 64-bit channel per module
DDR5
288 (notch in a different position)
262
1.1 V
Two independent 32-bit subchannels per module, on-die ECC, and an on-module power management IC
ECC vs. non-ECC RAM
ECC (error-correcting code) modules store extra bits, typically 72 bits per 64 bits of data, so the memory controller can detect and correct single-bit errors as they happen. ECC is standard in servers and workstations and requires both a compatible CPU and motherboard.
DDR5 on-die ECC corrects errors only inside each memory chip. A standard DDR5 module is not ECC RAM.
Channel configurations
Dual-channel and multi-channel memory are features of the CPU's memory controller and motherboard. Install matched modules in the slots the manual specifies, usually the same-colored slots, to enable them. Mismatched sizes or wrong slots can fall back to single-channel mode and reduce bandwidth.
Module 3: Virtualization and cloud computing
Know who manages what in each service model and how each deployment model is shared.
Service model
Provider manages
Customer manages
Examples
IaaS (Infrastructure as a Service)
Physical hardware, networking, storage, and virtualization
Operating system, middleware, runtime, applications, and data
AWS EC2, Azure Virtual Machines
PaaS (Platform as a Service)
Everything in IaaS plus the operating system and runtime
Applications and data
AWS Elastic Beanstalk, Heroku, Google App Engine
SaaS (Software as a Service)
The entire application stack
Application settings, user accounts, and data
Microsoft 365, Google Workspace, Salesforce
Deployment models
Public: multitenant infrastructure owned by a provider and delivered over the internet.
Private: single-tenant cloud dedicated to one organization, on premises or hosted.
Hybrid: public and private clouds connected so workloads and data can move between them, typically over a VPN or a dedicated link.
Community: shared by several organizations with common compliance or mission requirements.
Cloud characteristics
Elasticity: resources scale up and down automatically with demand.
Metered utilization: you pay for what you use, including ingress and egress data transfer.
Shared vs. dedicated resources: multitenant hardware vs. hardware reserved for one customer.
Availability and file synchronization across devices and locations.
Hypervisor classifications
The question to ask: is there a host operating system underneath the hypervisor?
Type 1 · Bare metal
Runs directly on hardware
Installs directly on the physical server without a general-purpose host operating system. It offers low overhead and high performance for enterprise and data center use.
VMware ESXi
Microsoft Hyper-V
Proxmox VE (KVM-based)
Type 2 · Hosted
Runs as an application
Installs on top of an existing operating system such as Windows, macOS, or Linux. It has more overhead but is ideal for testing, training, sandboxing, and running legacy software on a desktop.
Oracle VirtualBox
VMware Workstation
Parallels Desktop
Requirements: Virtualization needs CPU support (Intel VT-x or AMD-V) enabled in BIOS/UEFI, enough RAM and storage for every guest, and a virtual network configuration. Containers are different: they share the host's kernel instead of running a full guest operating system.
Part 2 · Core 2 (220-1202)
Module 4: Operating system administration and CLI tools
Windows commands are run in Command Prompt. Commands marked Extra are not in the V15 list but are standard repair tools.
# Network and connectivity diagnostics
ipconfig /all # Full TCP/IP configuration, MAC address, DHCP lease, and DNS servers
ipconfig /release # Releases the current DHCP lease
ipconfig /renew # Requests a new DHCP lease
ipconfig /flushdns # Clears the local DNS resolver cache
ping -t <target> # Pings continuously until stopped with Ctrl+C
tracert <target> # Shows each hop and its latency on the path to a destination
pathping <target> # Combines tracert with packet-loss statistics per hop
nslookup <domain> # Queries DNS for a domain's records
netstat -ano # Lists connections, listening ports, and owning process IDs (PIDs)
net use Z: \\server\share # Maps a network drive to a drive letter# Disk and system file integrity
sfc /scannow # Scans and repairs protected Windows system files
DISM /Online /Cleanup-Image /RestoreHealth # Extra: repairs the component store that sfc relies on
chkdsk C: /f # Fixes file system errors
chkdsk C: /r # Locates bad sectors and recovers readable data (includes /f)
diskpart # Interactive partition and volume management# Policy, users, and processes
gpupdate /force # Reapplies all Group Policy settings immediately
gpresult /r # Summarizes the Group Policy Objects applied to the user and computer
whoami # Shows the signed-in user account
net user # Lists or manages local user accounts
tasklist # Extra: lists running processes and their PIDs
taskkill /PID <id> /F # Extra: forcibly ends a process by PID
<command> /? # Shows help for any command
Repair order: If sfc /scannow reports files it cannot fix, run DISM /Online /Cleanup-Image /RestoreHealth to repair the source image, then run sfc /scannow again.
Lists files with permissions, prints the current directory, and changes directories
cp, mv, rm
Copies, moves or renames, and deletes files
chmod 755 <file>
Sets permissions: owner read, write, and execute (7); group and others read and execute (5)
chown <user>:<group> <file>
Changes a file's owner and group
grep "<term>" <file>
Searches text for lines that match a pattern
find / -name <file>
Searches the file system for files by name and other attributes
sudo, su
Runs one command with root privileges, or switches to another user account
apt, dnf
Installs and updates packages on Debian/Ubuntu and Fedora/RHEL systems
ps aux, top
Lists all processes, or shows a live view of CPU and memory use
kill -9 <PID>Extra
Sends SIGKILL to force a process to stop
df -h, du -sh
Shows free disk space per file system, and the size of a directory
ip a, ping, dig, curl, traceroute
Shows interfaces and addresses, tests reachability, queries DNS, fetches URLs, and traces routes
fsck, mount
Checks and repairs a file system, and attaches a file system to a directory
man, cat, nano
Opens a command's manual, prints file contents, and edits text files
Key files:/etc/passwd stores user accounts, /etc/shadow stores password hashes, /etc/hosts maps names to IPs locally, /etc/fstab defines file systems mounted at boot, and /etc/resolv.conf lists DNS servers.
Module 5: Security fundamentals and threat response
Social engineering targets people rather than systems. Learn the delivery method that defines each attack.
Attack
How it works
Best defense
Phishing
Mass emails that lure victims into clicking malicious links or entering credentials
User training, email filtering, MFA
Spear phishing
Phishing tailored to a specific person or organization
Verify unusual requests through a second channel
Whaling
Spear phishing aimed at executives such as CEOs and CFOs
Social engineering by voice call (vishing) or SMS text message (smishing)
Never share credentials by phone or text; call back on a known number
QR code phishing
A QR code leads to a malicious site or download
Check the URL before opening; avoid codes from untrusted sources
Business email compromise (BEC)
A compromised or spoofed business account requests payments or data
Out-of-band verification of payment changes
Pharming Extra
Poisoned DNS or a modified hosts file silently redirects users to a fake site
Secure DNS, check certificates, protect the hosts file
Tailgating / piggybacking
Following an authorized person through a secured door
Access control vestibules, badge policies, security guards
Shoulder surfing
Watching someone enter passwords or view sensitive data
Privacy screens, awareness of surroundings
Dumpster diving
Searching discarded materials for sensitive information
Shredding and secure disposal policies
Evil twin
A rogue access point that imitates a legitimate SSID
WPA3 or WPA2-Enterprise, VPN on public Wi-Fi
Wireless security protocols and authentication
Choose the strongest protocol every device supports. WEP and WPA (TKIP) are obsolete.
Wi-Fi encryption
WPA2: uses AES (CCMP). Personal mode uses a pre-shared key; Enterprise mode authenticates each user through 802.1X and RADIUS.
WPA3: replaces the pre-shared key handshake with SAE, which resists offline password guessing and adds forward secrecy. It is required for 6 GHz Wi-Fi.
TKIP: the legacy WPA cipher; avoid it and choose AES.
Authentication services
RADIUS (UDP 1812/1813): centralized AAA for Wi-Fi, VPN, and network access; encrypts only the password.
TACACS+ (TCP 49): Cisco-developed AAA, encrypts the entire payload, and separates authentication, authorization, and accounting. Common for network device administration.
Kerberos (port 88): ticket-based authentication used by Active Directory. Requires accurate time synchronization.
CompTIA malware removal procedure
Core 2 tests this sequence for a SOHO computer. Scenario questions often ask which step comes first or next, so learn the order and the reason for each step.
Investigate and verify malware symptoms. Look for pop-ups, browser redirection, unknown processes, disabled security tools, and altered or missing files.
Quarantine the infected system. Disconnect it from the network (Ethernet, Wi-Fi, and Bluetooth) and stop using removable media with it, so the malware cannot spread.
Disable System Restore in Windows Home. Infected restore points could otherwise reintroduce the malware later.
Remediate the infected system. Update anti-malware definitions, scan and remove threats using safe mode or a preinstallation environment, and reimage or reinstall the operating system if the infection cannot be removed reliably.
Schedule scans and run updates. Apply operating system and application updates, and confirm that real-time protection and scheduled scans are on.
Enable System Restore and create a restore point in Windows Home. This creates a clean recovery baseline.
Educate the end user. Explain how the infection likely happened and how to recognize phishing and unsafe downloads.
A common trap: updating anti-malware definitions is part of remediation (step 4), after the system is already quarantined and System Restore is disabled. Do not choose it as the first step.
Frequently asked questions
Are these notes for 220-1101/1102 or 220-1201/1202?
These notes follow the current V15 objectives for Core 1 (220-1201) and Core 2 (220-1202). Most of the material also applies to the retired 220-1101 and 220-1102 exams.
Do I need to memorize ports outside the official list?
Learn the 14 port entries in the official Core 1 list first. Ports marked Extra, such as 69, 123, 161/162, 514, 636, 993, and 995, are useful on the job and help with related questions, but they are not listed in the V15 objectives.
What is the difference between ECC RAM and DDR5 on-die ECC?
ECC RAM adds extra data bits so the memory controller can detect and correct errors on the module, and it requires motherboard and CPU support. DDR5 on-die ECC only corrects errors inside each memory chip, so a standard DDR5 module is not ECC RAM.
Continue the CompTIA A+ study path
Flashcards and practice exams are still being prepared.
NodnWebTools provides general informational, educational, and convenience resources. Calculations, conversions, estimates, and learning materials may contain errors or become outdated. Financial, tax, medical, legal, and travel information is not professional advice. Verify important results and current requirements with qualified professionals or authoritative sources. Protect sensitive files and personal information, review each tool’s privacy limitations, and use only content you are authorized to process. You are responsible for how you use and share results. Study resources are independent and do not guarantee exam success or imply certification-provider endorsement. CompTIA and A+ are trademarks of CompTIA, Inc. NodnWebTools is not affiliated with, endorsed by, or sponsored by CompTIA.
Module 5: Security fundamentals and threat response
Social engineering targets people rather than systems. Learn the delivery method that defines each attack.